# Elastic Agent in Fleet producing 1000s of log entries per hours about CA certs

**URL:** <https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576>\
**Category:** Elasticsearch\
**Tags:** fleet\
**Created:** [May 30, 2024, 7:57pm UTC](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576 "2024-05-30T19:57:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fstlouis](https://avatars.discourse-cdn.com/v4/letter/f/fbc32d/32.png) [@fstlouis](https://discuss.elastic.co/u/fstlouis)\
**Post date:** [May 30, 2024, 7:57pm UTC](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576/1 "2024-05-30T19:57:54Z")

</div>

I'm starting an on premise Elastic 8.12 deployment. I'm using Fleet managed agents with my own certificates (Entrust).  
I currentely have about 10 agents enrolled.  
I've noticed that I'm getting a very high volume of the following messages in my logs

```auto
CA certificate matching 'ca_trusted_fingerprint' found, adding it to 'certificate_authorities'
'ca_trusted_fingerprint' set, looking for matching fingerprints

```

Agents were enrolled with the following command

```auto
sudo ./elastic-agent install \
  --url=https:// ****servername.serverdomain****** :8220 \
  --certificate-authorities=/opt/ek_certs/EntrustIntermediate.cer \
  --enrollment-token= **************************

```

Is there an issue? Can those log entries be suppressed?

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [June 8, 2024, 2:40pm UTC](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576/2 "2024-06-08T14:40:11Z")

</div>

I can confirm that I'm also seeing these messages approximately every 5-10 seconds:

```auto
{"log.level":"info","@timestamp":"2024-06-08T17:37:43.990+0300","message":"'ca_trusted_fingerprint' set, looking for matching fingerprints","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"service.name":"filebeat","ecs.version":"1.6.0","log.logger":"tls","log.origin":{"file.line":179,"file.name":"tlscommon/tls_config.go","function":"github.com/elastic/elastic-agent-libs/transport/tlscommon.trustRootCA"},"ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-06-08T17:37:43.990+0300","message":"CA certificate matching 'ca_trusted_fingerprint' found, adding it to 'certificate_authorities'","component":{"binary":"filebeat","dataset":"elastic_agent.filebeat","id":"filestream-monitoring","type":"filestream"},"log":{"source":"filestream-monitoring"},"log.logger":"tls","log.origin":{"file.line":199,"file.name":"tlscommon/tls_config.go","function":"github.com/elastic/elastic-agent-libs/transport/tlscommon.trustRootCA"},"service.name":"filebeat","ecs.version":"1.6.0","ecs.version":"1.6.0"}
{"log.level":"info","@timestamp":"2024-06-08T14:37:47.624Z","message":"Running on policy with Fleet Server integration: fleet-server-policy","component":{"binary":"fleet-server","dataset":"elastic_agent.fleet_server","id":"fleet-server-default","type":"fleet-server"},"log":{"source":"fleet-server-default"},"ecs.version":"1.6.0","service.name":"fleet-server","service.type":"fleet-server","state":"HEALTHY","ecs.version":"1.6.0"}

```

I'm running Fleet-server enabled Elastic Agent 8.13.4 as a Docker container.

---

<div class="post-metadata">

**Author:** ![idan\_amar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/idan_amar/32/131806_2.png) [@idan\_amar](https://discuss.elastic.co/u/idan_amar)\
**Post date:** [June 8, 2024, 4:39pm UTC](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576/3 "2024-06-08T16:39:09Z")

</div>

same here.

---

<div class="post-metadata">

**Author:** ![tdanno](https://avatars.discourse-cdn.com/v4/letter/t/f0a364/32.png) [@tdanno](https://discuss.elastic.co/u/tdanno)\
**Post date:** [June 11, 2024, 9:09pm UTC](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576/4 "2024-06-11T21:09:36Z")

</div>

I'm seeing the same thing. 8.13.2 non-docker

---

<div class="post-metadata">

**Author:** ![lastshadow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lastshadow/32/130040_2.png) [@lastshadow](https://discuss.elastic.co/u/lastshadow)\
**Post date:** [December 5, 2024, 9:38pm UTC](https://discuss.elastic.co/t/elastic-agent-in-fleet-producing-1000s-of-log-entries-per-hours-about-ca-certs/360576/5 "2024-12-05T21:38:15Z")

</div>

Seeing the same thing. Did you ever find a solution?
